Impact
The vulnerability arises in an unknown function within /pages/pro_edit1.php of itsourcecode Sales and Inventory System, where an attacker can manipulate the prodcode argument to inject arbitrary SQL, enabling unauthorized query modification or data disclosure. The impact is potential compromise of database confidentiality and integrity, allowing attackers to read, modify, or delete inventory records. The flaw is a classic SQL injection weakness, as indicated by the CWE classifications.
Affected Systems
This flaw affects the itsourcecode Sales and Inventory System, specifically version 1.0 as referenced in the description. No other versions or products are listed as affected, so only installations of this exact release are currently at risk.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate severity, and the EPSS score of less than 1% indicates a very low exploit likelihood at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Attackers can launch the exploit remotely by crafting requests that alter the prodcode parameter. While the public disclosure has made the attack methodology known, the low EPSS score and absence from KEV mean the risk is moderate but currently low in probability.
OpenCVE Enrichment